CVE-2017-5489 on Ubuntu 16.04 LTS (xenial) - medium.
Description:
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.